SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • February 16, 2024
  • Rss Fetcher
The Wyze Cam OG (pictured left) and the Wyze Cam OG Telephoto 3x (right) on a black backdrop.
Image: Wyze

Five months ago, we wrote about how your Wyze webcam might have let strangers peek into your house. Today, it happened again. Wyze cofounder David Crosby confirmed the issue in an email response sent to The Verge, saying, “We have now identified a security issue where some users were able to see thumbnails of cameras that were not their own in the Events tab.”

After an extended outage that Wyze says stemmed from problems with AWS, ten different Redditors reported that their Wyze app showed them images from a security camera that wasn’t their own — giving them glimpses of a stranger’s porch or living room. Some of the videos were from entirely different timezones.

“One of my cameras notified me of an event from inside someone else home with them in it walking around,” begins one post. “I just got a motion detection notification with a picture for someone else’s house that isn’t mine!” reads another.

“So far we’ve collected 14 reports of this happening, but we are currently identifying all affected users…We will also send notification to all Wyze users explaining what happened,” writes Crosby. He linked the issue to overload and corruption of user data after an AWS outage this morning and said that it did not connect live feeds or send videos to the wrong users, just the alert thumbnails.

“As soon as we saw these reports we took down the Events tab. We then added in an extra layer of verification for each user before they could see thumbnails. To be extra safe, we are now force logging out all users who have used the Wyze app today to reset tokens,” writes Crosby. You can read his email in its entirety below.

“I’m able to see a random camera I do not have permission for,” reads a similar post in the Wyze forums. “Notification alert for a camera I don’t own,” a second one starts. Six users commented on other peoples’ Reddit posts to say they, too, were seeing these videos.

After the outage eased around mid-day Friday, the thumbnail issues started, as the company reported at 1:07PM ET, “We are still investigating an issue with the Events Tab and will have another update shortly with further info,” without explaining the issue.

At 2:27PM ET, the company turned off the Events tab entirely: “We are temporarily disabling the Event tab in the Wyze app to investigate a possible security issue and will have it back up soon,” it wrote in a service advisory. The company still made no mention of what the issue might be.

Two years ago, I told you how Wyze swept a security vulnerability under the rug for three years, never notifying its customers that their unpatchable v1 cameras could have theoretically let hackers access video feeds over the internet or that patches were required for later cameras to prevent the same thing.

Last September, The New York Times publicly stopped recommending Wyze cameras following our reporting, noting that Wyze never reached out to its customers or “provided meaningful details about the incident.”

Dave Crosby, Wyze Chief Marketing Officer:

Update: After an AWS outage this morning, our servers got overloaded and it corrupted some user data. We have now identified a security issue where some users were able to see thumbnails of cameras that were not their own in the Events tab. Fortunately, they were not able to view live streams or watch these videos, only the thumbnails were visible.

So far we’ve collected 14 reports of this happening, but we are currently identifying all affected users. These affected users will be notified asap. We will also send notification to all Wyze users explaining what happened.

As soon as we saw these reports we took down the Events tab. We then added in an extra layer of verification for each user before they could see thumbnails. To be extra safe, we are now force logging out all users who have used the Wyze app today to reset tokens.

We will explain in more detail once we finish investigating exactly how this happened and further steps we will take to make sure it doesn’t happen again. Again, we are very sorry for the inconvenience today. Thanks to everyone who helped report incidents and helped get devices back online. Our deepest apologies to everyone affected.

Update February 16th, 2024, 8:11PM ET: Added response from Wyze co-founder Dave Crosby confirming and detailing the problem.

Previous Post
Next Post

Recent Posts

  • Axiz Expands Communication Technology Portfolio with Jabra Partnership
  • Simon Black Appointed Board Chair at Onafriq
  • Fortnite returns to the US App Store after a five-year gap
  • Luminar kicks off another round of layoffs amid CEO’s sudden resignation
  • Host a tailored Side Event at TechCrunch All Stage 2025 in Boston

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.